mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Http_server | Apache | * | 1.3.30 (including) |
| Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | RedHat | * | |
| Red Hat Enterprise Linux ES version 2.1 | RedHat | * | |
| Red Hat Enterprise Linux WS version 2.1 | RedHat | * | |
| Red Hat Linux Advanced Workstation 2.1 | RedHat | * | |
| Red Hat Stronghold 4 | RedHat | * | |
| Stronghold 4.0 for Red Hat Enterprise Linux AS (version 2.1) | RedHat | * | |
| Apache | Ubuntu | dapper | * |
| Apache | Ubuntu | edgy | * |
| Apache | Ubuntu | feisty | * |